<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Affiliate Super Assistent (&lt;= 1.10.2) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/affiliate-super-assistent--1.10.2/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 01 Sep 2026 07:03:27 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/affiliate-super-assistent--1.10.2/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored Cross-Site Scripting Vulnerability in Affiliate Super Assistent WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-09-01-cve-2026-19573/</link><pubDate>Tue, 01 Sep 2026 07:03:27 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-01-cve-2026-19573/</guid><description>The Affiliate Super Assistent plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability via the doCommentShortcode function, allowing unauthenticated attackers to execute arbitrary scripts in the context of a victim's session.</description><content:encoded><![CDATA[<p>The Affiliate Super Assistent plugin for WordPress is vulnerable to a Stored Cross-Site Scripting (XSS) flaw identified as CVE-2026-19573. The issue exists within the ‘doCommentShortcode’ function, which fails to properly sanitize user-supplied input or escape output before rendering it in the browser. An unauthenticated attacker can leverage this weakness to inject malicious JavaScript into web pages served by the plugin. When a legitimate user or administrator views an affected page, the injected script executes within the victim's session, potentially leading to unauthorized actions, session hijacking, or the defacement of the site. This vulnerability affects all versions of the Affiliate Super Assistent plugin up to and including 1.10.2. Defending against this threat requires immediate patching or removal of the vulnerable plugin, as the lack of input sanitization provides a direct vector for script injection.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary web scripts in the browser of any user who visits the compromised page. This can lead to account takeover, the redirection of users to malicious domains, or the theft of sensitive session cookies. Given the nature of Stored XSS, these attacks persist until the malicious payload is manually removed from the database or the underlying vulnerability is remediated.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the Affiliate Super Assistent plugin to a version released after 1.10.2 to remediate CVE-2026-19573.</li>
<li>Audit database content associated with the Affiliate Super Assistent plugin for suspicious script tags or obfuscated JavaScript.</li>
<li>Monitor web server access logs for anomalous POST requests directed at endpoints responsible for comment submissions or form processing utilized by the plugin.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-vulnerability</category><category>xss</category><category>wordpress</category></item></channel></rss>